Incorrect permission assignment for critical resource in Harbor - #VU153946
Published: October 7, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote privileged user to read, modify, or delete resources across projects and take over project robot accounts, locking out their owners.
The vulnerability exists due to incorrect permission assignment in Harbor's system robot permission handling when processing project resource permissions with the cover all projects scope. A remote privileged user can exercise project read, update, or delete permissions as a global wildcard over resources inside every project, including changing robot permissions and resetting their secrets, to read, modify, or delete resources across projects and take over project robot accounts, locking out their owners.
Exploitation requires possession of a system robot account's token with the affected scope and project resource permissions. Robot accounts scoped to specific projects are not affected.